Agent skill

Agy Worker

by aiskillstore in aiskillstore/marketplace

A skill your agent uses when Codex or Claude Code should delegate repository exploration or implementation to Google Antigravity CLI (agy), then review, verify, repair, and deliver the result.

MITAuto-check passed

Install Agy Worker

skills CLI
$ npx skills add aiskillstore/marketplace --skill agy-worker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace agy-worker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pending/cagdasyurekli/agy-worker .claude/skills/agy-worker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agy-worker
GitHub stars
430
Token cost
~2.7k tokens
SKILL.md length
1,253 words
Files
41 (incl. scripts, references)
Skills in repo
1,044
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when Codex or Claude Code should delegate repository exploration or implementation to Google Antigravity CLI (agy), then review, verify, repair, and deliver the result.

  • Claude Code should delegate repository exploration
  • SKILL.md covers Authorize provider work, Choose and run the workflow and Hard stops and delivery
  • Runs Shell scripts from its folder; calls bash and claude
  • Implementation to Google Antigravity CLI (agy)

What it does

Agy Worker is an agent skill from aiskillstore/marketplace. Use when Codex or Claude Code should delegate repository exploration or implementation to Google Antigravity CLI (agy), then review, verify, repair, and deliver the result.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 44 other files, including scripts and reference files (for example `README.md`, `agents/openai.yaml` and `references/PROJECT_LIFECYCLE_AND_VERIFICATION.md`). Compatibility notes: OpenAI Codex CLI and Claude Code. Requires Bash, Python 3, git, and agy with provider network access.

The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is MIT.

When your agent uses it

  • Claude Code should delegate repository exploration
  • Implementation to Google Antigravity CLI (agy)
  • Deliver the result

Example prompts

  • “/agy-worker”

Requirements

  • Python 3
  • A Bash shell
  • Compatibility (from SKILL.md): OpenAI Codex CLI and Claude Code. Requires Bash, Python 3, git, and agy with provider network access.

What it can do on your machine

Read from SKILL.md and the folder at commit 755bc35. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    OpenAI Codex CLI and Claude Code. Requires Bash, Python 3, git, and agy with provider network access.

    From compatibility in the SKILL.md frontmatter.

Context cost

Agy Worker loads about 2.7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 46 tokens; SKILL.md has 1,253 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aiskillstore/marketplace at commit 755bc35, republished under its MIT licence (© aiskillstore). 1,253 words, ~2,697 tokens.

Download SKILL.mdSave it as .claude/skills/agy-worker/SKILL.md (or your agent's skills folder). This skill also uses 40 other files; get the full folder from GitHub.
name
agy-worker
description
Use when Codex or Claude Code should delegate repository exploration or implementation to Google Antigravity CLI (agy), then review, verify, repair, and deliver the result.
compatibility
OpenAI Codex CLI and Claude Code. Requires Bash, Python 3, git, and agy with provider network access.
license
MIT
metadata.author
cagdasyurekli
metadata.version
0.24.0

Delegate repository work and verify the result

Delegate substantive exploration or implementation to agy, then inspect its diff and run driver-owned checks. Unknown files, architecture or a first test command do not prevent useful exploration; worker envelopes are not evidence.

SKILL_ROOT contains this file. In Claude Code it is ${CLAUDE_SKILL_DIR}, substituted in instructions rather than exported by Bash. Resolve the package:

bash
PIPELINE="$(bash "$SKILL_ROOT/scripts/resolve-pipeline.sh")" || exit $?

Use "$PIPELINE/doctor.sh" --repo /absolute/path/to/target for offline readiness; ready proves neither authentication nor task success. See the Package README.

Authorize provider work

Obtain human approval for the task, exact provider-readable content, transmission and isolation modes, caller-selected model and budget. One upfront approval may cover predictable same-scope repairs and mechanical digest refresh. New scope, content exposure, destination, isolation, permissions or budget needs fresh authority. SHA values bind the documented controller inputs, not the entire human decision; refreshing a still-applicable binding is not another approval request. Goal and hand-authored JSON are not ordinary-use prerequisites.

Prefer --provider-scope FILE --approve-transmission-sha SHA256 for bounded jobs. It binds reviewed read entries, their content digest, and a write subset in a fresh owner-private mode-0700 Gitless stage. Whole-worktree dispatch requires --approve-whole-worktree LAUNCH_APPROVAL_SHA256. Every disposable-worktree entry is provider-readable and may reach Google/Gemini; --add-dir, prompt denylists and gate path policies do not narrow that read boundary. Neither workflow.sh run nor the advanced agy-worker.sh initial dispatch has an implicit transmission mode. The whole-worktree digest binds content, kinds, full file mode bits, symlink target hashes, the readable manifest, provider isolation and native grant profile. The scoped digest binds canonical read/write policy, readable path/kind manifest, selected bytes and executable bits, isolation and grant profile; scoped mode rejects symlinks and does not bind full POSIX permissions. The controller rechecks the approved boundary before provider start. The human approves one launch_approval_sha256 over canonical launch_authority: those content inputs, destination and Git base, exact normalized task and constructed prompt, fixed transport templates, workflow/edit mode, model/effort, cycles and time budgets, scoped repair, self-verification manifest digest, provider-env names, slash policy, additional directories and provider schema digest. Preview the exact task and all launch options; reuse them unchanged for the approved run. Only trailing LF bytes are removed from UTF-8 task input; spaces and CRLF are preserved. Environment values and private verification commands are never serialized into the approval payload. Use the private prelaunch review checklist in Project lifecycle and verification, including any optional self-verification commands, IDs and limits; keep that manifest out of the provider preview and prompt. Retired dispatch and workflow job formats are rejected; finish or discard them with their creating release, without migration. Default --provider-isolation session uses the existing AGY session. AGY has normal user filesystem/network authority; staging and reconciliation are not host isolation. Explicit --provider-isolation native requires supported macOS scoped containment; it never falls back to session mode. Preserve the recorded isolation mode and grant profile across repairs. Provider-scope approval grants neither provider execution, Git action, driver acceptance, nor publication. Exclude secrets, denied paths and unrelated private content from every approved entry; telling the worker not to read an approved entry is not a control.

Keep raw logs and controller state outside the worktree and prompts. Each launch requires capability preflight and immediate executable-binding recheck. Model and effort stay caller-owned. Child environment opt-ins require approval per variable name. Installation grants no provider or Git authority.

Read Security and compatibility before a first live dispatch or changing execution exposure. It owns native network/Keychain limits, verifier environments and no-follow boundaries. Read the required launch notices before initial, resume, continue or restart attempts; notices do not repeat approvals.

Show full SKILL.md (673 more words)Show less

Choose and run the workflow

IntentWorkflowCycle budgetDriver action
Explore, understand, review or planexploredefault 2, allowed 1..2Spot-check findings; state coverage limits.
Bounded feature, refactor or teststaskdefault 2, allowed 1..2Review the diff; run relevant checks.
Project build or broad audit-and-fixprojectdefault 5, allowed 1..5Review changes; run build, tests and lint.

Use workflow.sh run --preview, approved run, read-only status, and verify-finalize. The facade does not choose a model, assurance, repair or external action. Project lifecycle and verification owns copyable commands, Verification v2 candidate bindings and recovery.

Quick path: save the reviewed scope file outside the target repository with mode 0600, then run the facade with a unique job ID:

bash
TARGET=/absolute/path/to/approved-repository
JOB_ID=job-12345
SCOPE=/absolute/private/provider-scope.json
TASK='the exact approved bounded task'
"$PIPELINE/workflow.sh" run --preview --repo "$TARGET" --job-id "$JOB_ID" --provider-scope "$SCOPE" --task "$TASK"

This creates the disposable worktree and private state. Review launch_approval_sha256, then repeat the same command without --preview, adding --approve-transmission-sha "$LAUNCH_SHA". A minimal owner-private scope file, with entries sorted by path, is:

json
{"schema_version":1,"kind":"agy-worker-provider-scope","read":[{"path":"src/parser.py","kind":"file"},{"path":"tests","kind":"tree"}],"write":[{"path":"tests","kind":"tree"}]}

Use paths that exist in the reviewed worktree and keep the scope file outside it with mode 0600. The facade derives an owner-private state path for later status and verify-finalize; see the linked guide for the complete sequence.

Run driver-selected build/test commands and Python imports in an isolated verification copy with PYTHONDONTWRITEBYTECODE=1. Inspect the bound candidate's actual diff and gate binding directly. Never manually edit, delete, or chmod the bound candidate; send needed repairs to the same worker conversation. Never execute an envelope's commands_run or tests_run; bind only sanitized driver findings to the candidate. Gate and verify-finalize --verify-argv verifiers run in the bound candidate: choose only commands known to be read-only there. Snapshot rejection detects changes to bound candidate state after they happen; it does not isolate the candidate. Verifiers run untrusted candidate code with the user's authority; the gate does not detect changes outside the candidate, including Git hooks and configuration. Feed separate copy test results into Verification v2. Repair observable failures in the same conversation within budget; never silently fall back to direct-driver work after provider failure or exhausted budget. Use initial --allow-scoped-repair for approved multi-turn scoped work. Without that grant, a changed scoped candidate is result/finalize-only. Preserve useful work; restart requires an explicit user decision.

Self-verification is optional advisory feedback, not acceptance. An unknown first check is not a hard stop. Reuse checks only for unchanged candidate bytes and relevant environment; the driver independently decides the final assurance. For trust-boundary changes, use the short design note and independent review in Material planning governance. Explicit delegation-first requires running the delegation-policy.sh evaluator before substantive repository work. Controller records are local: the runtime cannot infer prior work or approval and must never silently authorize direct-driver fallback after missing approval, a hard stop, preflight/provider failure or exhausted budget.

Claude Code: in non-interactive claude -p or SDK runs, dispatch in the foreground (up to the host's ten-minute ceiling) or keep the turn alive until it finishes; never end the turn while a job runs. In interactive sessions, a long dispatch may use Bash run_in_background: true while the main session remains active. Do not duplicate a job or treat a Bash timeout as provider failure. Bash permission approval is separate from transmission approval. Read Claude Code host operation.

Hard stops and delivery

Stop for missing exact approval; secrets or denied/unrelated private content in approved inputs; writes escaping the worktree, entering .git or traversing symlink boundaries; or unapproved Git, publication, installation, account or external actions. Never use dangerous permission/approval-bypass flags or disable the host sandbox for AGY. Do not modify user configuration as a code change. Never weaken the evidence gate.

Before changing AGY-facing flags or claims, run "$PIPELINE/ground-truth.sh" and inspect current help. Its default version/help phase is local; --account is separate. Read result.structured_output, not echoed schema or empty display text.

Deliver verified, partially_verified, rejected or blocked with the checks actually run and remaining gaps. Offline checks do not prove live provider behavior, completeness, release state or general correctness. Use Troubleshooting for the failing boundary. When status offers finalization for a bound candidate, verify-finalize records the driver's result without a Git change and is the facade's required closure step.

© aiskillstore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 40 other files (scripts, references) in pending/cagdasyurekli/agy-worker of aiskillstore/marketplace.

  • SKILL.md
  • README.md
  • agents/openai.yaml
  • references/PROJECT_LIFECYCLE_AND_VERIFICATION.md
  • references/SECURITY_AND_COMPATIBILITY.md
  • references/TROUBLESHOOTING.md
  • runtime/agy-worker.sh
  • runtime/delegation-policy.sh
  • runtime/doctor.sh
  • runtime/evidence-report.sh
  • runtime/ground-truth.sh
  • runtime/job.sh
  • runtime/model-selection.sh
  • runtime/qa-gate.sh
  • runtime/schemas/delegation-policy.schema.json
  • runtime/schemas/evidence-receipt.schema.json
  • runtime/schemas/job-state.schema.json
  • … and 24 more

Open the folder on GitHubat commit 755bc35

Compare with similar skills

Agy Worker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agy Worker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agy Worker this skillaiskillstore/marketplace430—~2.7kAutomated safety check: PassMIT
Agy Delegatesickn33/agentic-awesome-skills47k1 repos~2.2kAutomated safety check: PassMIT
Agy DelegateamElnagdy/delegate-skills2.3k—~2.5kAutomated safety check: PassMIT
Agy Autosickn33/agentic-awesome-skills47k1 repos~1.9kAutomated safety check: WarnMIT
Delegate Workpaperclipai/paperclip99k—~372Automated safety check: PassMIT
Worker Visualizernexu-io/open-design100k—~998Automated safety check: PassApache-2.0

Similar skills

  • Agy Delegate

    sickn33/agentic-awesome-skills

    Delegate coding tasks to the Google Antigravity CLI (agy) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.

    47k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Agy Delegate

    amElnagdy/delegate-skills

    Delegate a coding task to the Google Antigravity CLI (agy) as a background implementer, then review its diff and land it yourself.

    2.3k GitHub stars~2.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Agy Auto

    sickn33/agentic-awesome-skills

    Configure agy-auto PreToolUse security gate to run Antigravity CLI (agy) unattended with layered policy controls instead of --dangerously-skip-permissions.

    47k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check: warnings
  • Delegate Work

    paperclipai/paperclip

    Delegate user-requested work to an existing Paperclip agent, with a durable task reference and clear execution expectations.

    99k GitHub stars~372 tokensUpdated today
    Auto-check passed
  • Worker Visualizer

    nexu-io/open-design

    A real-time data/particle/simulation visualizer whose heavy compute runs in a Web Worker (off the main thread), optionally sharing memory with the UI via SharedArrayBuffer, and renders to a canvas…

    100k GitHub stars~998 tokensUpdated today
    Auto-check passed
  • Agent skill for worker-specialist - invoke with $agent-worker-specialist

    74k GitHub starsUsed in 2 repos~1.4k tokens
    Auto-check passed

More from aiskillstore/marketplace

All 1,044 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 1 repo~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Project Planner

    aiskillstore/marketplace

    Detects stale project plans and suggests session commands. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~504 tokens
    Auto-check passed

Questions about Agy Worker

What does Agy Worker do?

A skill your agent uses when Codex or Claude Code should delegate repository exploration or implementation to Google Antigravity CLI (agy), then review, verify, repair, and deliver the result. Agy Worker is an agent skill from aiskillstore/marketplace. Use when Codex or Claude Code should delegate repository exploration or implementation to Google Antigravity CLI (agy), then review, verify, repair, and deliver the result.

When should I use Agy Worker?

Agy Worker fits situations like: Claude Code should delegate repository exploration; implementation to Google Antigravity CLI (agy); deliver the result.

How do I install Agy Worker in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill agy-worker -a claude-code`. Or copy the skill folder (pending/cagdasyurekli/agy-worker in aiskillstore/marketplace) into .claude/skills/agy-worker in your project. Claude Code loads it when a task matches its description.

How do I install Agy Worker in Codex?

Run `npx skills add aiskillstore/marketplace --skill agy-worker -a codex`. Or copy the skill folder (pending/cagdasyurekli/agy-worker in aiskillstore/marketplace) into .agents/skills/agy-worker in your project. Codex loads it when a task matches its description.

Can I use Agy Worker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill agy-worker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agy-worker, .gemini/skills/agy-worker, .github/skills/agy-worker and .opencode/skills/agy-worker in your project.

What does Agy Worker need to run?

Going by SKILL.md and its folder, Agy Worker needs a shell for the scripts in its folder and the command-line tools its instructions call (bash and claude). Our summary lists: Python 3; A Bash shell. Compatibility (from SKILL.md): OpenAI Codex CLI and Claude Code. Requires Bash, Python 3, git, and agy with provider network access..

Does Agy Worker access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agy Worker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Agy Worker use?

Agy Worker is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agy Worker use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Agy Worker?

Skills that share tags, products or a category with Agy Worker: Agy Delegate (sickn33/agentic-awesome-skills, 47k stars), Agy Delegate (amElnagdy/delegate-skills, 2.3k stars), Agy Auto (sickn33/agentic-awesome-skills, 47k stars) and Delegate Work (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agy Worker?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,044 skills in this directory. The repository was last updated on October 9, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.